Lune

ACM MM2023Top-tier venue

Free Fine-tuning: A Plug-and-Play Watermarking Scheme for Deep Neural Networks

Run Wang, Jixing Ren, Boheng Li, Tianyi She, Wenhui Zhang, Liming Fang, Jing Chen, Lina Wang

2023Year
20Citations
8Top-tier citations

Abstract

Watermarking has been widely adopted for protecting the intellectual property (IP) of Deep Neural Networks (DNN) to defend the unauthorized distribution. Unfortunately, the popular datapoisoning DNN watermarking scheme relies on target model finetuning to embed watermarks, which limits its practical applications in tackling real-world tasks. Specifically, the learning of watermarks via tedious model fine-tuning on a poisoned dataset (carefullycrafted sample-label pairs) is not efficient in tackling the tasks on challenging datasets and production-level DNN model protection.

To address the aforementioned limitations, in this paper, we propose a plug-and-play watermarking scheme for DNN models by injecting an independent proprietary model into the target model to serve the watermark embedding and ownership verification. In contrast to the prior studies, our proposed method by incorporating a proprietary model is free of target model fine-tuning without involving any parameters update of the target model, thus the fidelity is well preserved. Furthermore, our method is scaleable to challenging datasets, large production-level models, and diverse tasks (e.g., speaker recognition). Experimental results on real-world challenging datasets (e.g., ImageNet) and real-world DNN models demonstrated its effectiveness, fidelity w.r.t. the functionality preserving of the target model, robustness against popular watermark removal attacks (i.e., fine-tuning attack, pruning, input preprocessing), and the plug-and-play deployment. Our proposed watermarking scheme also outperforms the two competitive baselines in terms of fidelity preserving and robustness against watermark removal attacks. Our research findings reveal that model fine-tuning with poisoned data is not prepared for the IP protection of DNN models deployed in real-world tasks and poses a new research direction toward a more thorough understanding and investigation of adopting the proprietary model for DNN watermarking. The source code and models are available at https://github.com/AntigoneRandy/PTYNet.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 88639b5a-cfec-40ef-b300-374aee314d7d

Cited by top-tier papers8

Ask how each one uses it

Builds on18

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines